China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade - The Hacker News
A decade-long backdoor in Linux login software just exposed. Here's why your AI infrastructure is vulnerable.

Why it matters
Supply chain security in critical infrastructure is directly relevant to AI companies building on Linux systems and cloud platforms. A nearly 10-year undetected compromise of foundational software raises urgent questions about software bill-of-materials (SBOM) audit practices that AI labs depend on for secure model deployment and data center operations.
The key facts
10 to knowChina-linked hackers backdoored Linux login software (xz Utils)
Compromise remained undetected for nearly a decade
Affects foundational infrastructure used across AI data centers and cloud platforms
Highlights supply chain vulnerability in open-source software critical to AI ops
Published June 12, 2026
China-linked threat actor identified
Backdoor embedded in Linux login software
Nearly decade-long undetected presence (approximately 10 years)
Supply chain attack on widely-used authentication layer
Affects Linux systems across enterprises and AI infrastructure providers
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade The Hacker News

